{% extends "base.html" %} {% from "_macros.html" import no_data with context %} {% block title %}Visual{% endblock %} {% block content %}

Visual

{% set extended = view_mode == 'extended' %} {% if not snap %} {{ no_data() }} {% elif not tree %}
No VPCs {{ 'in the active scope' if scope_count else 'found in this snapshot' }}.
{% else %} {% if extended %}

Extended view

Regional services (SNS, SQS, DynamoDB, EventBridge, S3, API Gateway, Step Functions, Lambda, ECS, Secrets Manager names, Kafka: MSK clusters and self-managed brokers feeding Lambda event source mappings) are drawn outside the VPC; Transit Gateway, peering and internet via NAT as external nodes. Every connection carries evidence: {% for level in evidence_levels %}{{ evidence_labels[level] }} ({{ evidence_help[level] }}){{ ' > ' if not loop.last }}{% endfor %}. Environment variables and IAM policies are only matched against known resource names and ARNs: their values are never stored or shown. IAM Resource: "*" appears as a broad access badge and is never expanded.

{% if crawl %}Services crawled {{ crawl.crawled_at | localtime }} for snapshot #{{ snap.id }} · {{ crawl.sources | length }} source(s) read · {{ crawl.warnings | length }} warning(s). {% if crawl.capped %}⚠ {{ crawl.capped | length }} capped{% endif %} {% else %}Not crawled for snapshot #{{ snap.id }} yet: read-only, each source is optional (a missing permission or disabled feature is a warning).{% endif %}
{% if crawl and crawl.warnings %}
{{ crawl.warnings | length }} crawl warning(s){% if crawl.capped %} · {{ crawl.capped | length }} source(s) capped{% endif %}
{% endif %}
Flow logs (opt-in, observed evidence) Queries this VPC's flow logs in CloudWatch Logs Insights (billed per GB scanned). Only ENI↔ENI/port aggregates are stored, never raw records.
{% endif %}
{% if extended %}{% endif %}
{% if extended %}
Focus
{% endif %}
Borders
Labels
Environment Loading…
Group by
Connections {# Always sent, so "no box ticked" survives a VPC change instead of meaning "all". #} {% for t in edge_types %} {% endfor %}
{% if extended %}
Evidence {% for level in evidence_levels %} {% endfor %}
Services Crawl services to list them.
{% endif %}
Scroll to zoom, drag to pan, hover for full names. Click a resource to highlight its connections (click the background to clear); double-click it to open its ENI. Click a group (more than 10 resources of one type in a subnet) to expand or collapse it. Solid lines are load balancer targets and ECS services; dashed lines are security group based: endpoint reach (the endpoint's security group allows tcp/443 from the resource) and SG references. Drag resources to rearrange them: positions are saved for this account, VPC, view and layout, and restored when the page is opened with that layout until you press Reset layout; choosing another layout always lays the diagram out afresh. Fit shows every visible node. Layout (Grid by default) and the expanded groups are remembered per account and view. Full names are shown, wrapped at - _ . /; Shorten long names cuts them in the middle instead. Border, legend and label toggles are remembered per account. Endpoint reach lines are labelled with the endpoint's security group name. Group by draws a dashed box (and a coloured outline) around the resources sharing a security group, a tag value, a Terraform root (loaded under Settings), an environment (colour per environment), an owner (ownership source and value: CloudFormation stack, IaC tag, Terraform, CloudTrail creator or unmanaged — see the Ownership page) or a team (the team tag key of Settings → Ownership). Environment shows only the ticked environments (from the Terraform root × environment mapping, else the environment tag set in Settings). Exports contain the diagram as currently shown; with Expand all groups (default) every collapsed group is exported as its member resources. {% if extended %}
Extended view: one line per pair of nodes, styled by its strongest ticked evidence; +N counts further evidence lines. Only Observed and Configured are shown by default; the Evidence filter is remembered per account. Click a connection (or a service node) to list all of its evidence below the diagram. Regional services of one type and Lambda / ECS ENIs of a subnet are groups: click to expand or collapse; lines between collapsed groups merge into one, labelled ×count and drawn wider. Click a node (double-click a group), or search by name, ARN or IP, to show only it and its 1- or 2-hop neighbourhood; Show all, Esc or Reset layout returns to the full diagram. The Hierarchy layout runs left to right: sources (EventBridge, SNS, API Gateway, S3) → compute (Lambda, ECS) → targets; the other layouts keep every box (VPC, subnet, expanded service group, swimlane) together as one block. Group by tag or Terraform root draws one swimlane per app. Exports contain exactly what is shown (focus, groups and filters). Crawled regional nodes linked to nothing in this VPC are listed under Not linked beside the diagram: click one to draw it, or tick Show all crawled nodes.{% endif %}
{% if extended %} {% endif %}
{% if extended %} {% endif %}

Legend

{% for label, icon in legend_icons %} {{ label }} {% endfor %}
VPC Subnet Idle ENI (available) Group (click to expand) Group by: security group / tag / Terraform root / owner / team {% if not extended %} {% for t in edge_types %} {{ edge_labels[t] }} {% endfor %} {% endif %}
{% if extended %}
{% for level in evidence_levels %} {{ evidence_labels[level] }}: {{ evidence_help[level] }} {% endfor %}
Expanded service group (click its title to collapse) Swimlane: one app (group by tag / Terraform root) ×N: N merged connections (wider = more) broad access an IAM statement allows Resource "*" (not expanded)
{% endif %}

Icons: AWS Architecture Icons, © Amazon Web Services, Inc. or its affiliates. Layout: dagre (MIT).

{% endif %} {% endblock %}